Fedora Coturn 4.15.0 Security Advisory Addresses STUN Vulnerabilities

Fedora Coturn 4.15.0 Security Advisory Addresses STUN Vulnerabilities

First seen 3 Aug 2026, 06:02 UTC Linuxsecurity 99% similarity 57.8

Article Content

Browse articles
ThreatCluster

Fedora released a security advisory for Coturn version 4.15.0, addressing critical vulnerabilities related to STUN attributes processing. The vulnerabilities allowed Coturn to incorrectly handle attributes following MESSAGE-INTEGRITY, potentially leading to interoperability issues. This advisory affects users of the Coturn TURN server, which is widely used for VoIP and NAT traversal. Key fixes include rejecting ACME requests properly and ensuring session resumes are bound to original allocation owners. The update is available for installation via the 'dnf' package manager. Users are urged to apply the update to mitigate potential risks. The advisory also highlights several other bug fixes related to message handling and buffer management.

Key Points: • Fedora's Coturn 4.15.0 addresses critical STUN attribute handling vulnerabilities. • The advisory includes fixes for interoperability issues and session management. • Users are advised to update their Coturn installations promptly to mitigate risks.

ThreatCluster AI How this analysis works

Timeline

2026-07-24
Coturn 4.15.0 released
Fedora released Coturn version 4.15.0, which includes critical security fixes for STUN attributes handling.
Linuxsecurity
2026-08-02
Security advisory published
Fedora issued a security advisory detailing vulnerabilities in Coturn 4.15.0 related to STUN attributes.
Linuxsecurity

Community

Browse all →

Tracked Entities in This Story